CVE-2020-15521
Description
Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Zoho ManageEngine Applications Manager before build 14730 is vulnerable to stored XSS via jsp/header.jsp.
Vulnerability
Zoho ManageEngine Applications Manager before version 14 build 14730 is vulnerable to stored cross-site scripting (XSS) in the jsp/header.jsp component. The application fails to sanitize user-supplied input before rendering it in the header, allowing an attacker to inject arbitrary HTML or JavaScript. This affects all versions prior to build 14730 [2].
Exploitation
An attacker must be authenticated to the Applications Manager console. The attacker can inject malicious script into a field that is later displayed in jsp/header.jsp. When other administrators view the affected page, the script executes in their browser session. No additional user interaction beyond viewing the page is required.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session. This can lead to theft of session cookies, manipulation of the application interface, or further actions such as creating new admin accounts or exfiltrating sensitive data.
Mitigation
The vulnerability is fixed in Zoho ManageEngine Applications Manager build 14730 (version 14) and later. Users should upgrade to this build or newer. No workarounds are documented in the available references [2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zoho/ManageEngine Applications Managerdescription
- Range: <14 build 14730
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.manageengine.commitrex_refsource_MISC
- www.manageengine.com/products/applications_manager/issues.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.